[113575] in North American Network Operators' Group
Re: SIP - perhaps botnet? anyone else seeing this?
daemon@ATHENA.MIT.EDU (Gadi Evron)
Wed Apr 15 16:51:10 2009
Date: Wed, 15 Apr 2009 23:03:25 +0300
From: Gadi Evron <ge@linuxbox.org>
To: "Leland E. Vandervort" <leland@taranta.discpro.org>
In-Reply-To: <Pine.LNX.4.44.0904151637230.27106-100000@taranta.discpro.org>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
Leland E. Vandervort wrote:
>
> Managed to get to the bottom of it, and it was indeed a SIP User-Agent
> brute-force attempt. Interestingly, though, that your mail mentions
> specifically verizon... the majority of the remote addresses during this
> brute-force attempt were also behind verizon... coincidence?
>
> Hmm..
There are at least two projects I'm aware of and some tools
released/getting released working on war-dialing over SIP.
One tool to take a look at and see if it fits the bill is WarVOX from
Metasploit's HD Moore.
http://www.warvox.org/index.html
Gadi.